Earlier quoted context omitted.
DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.
Does all this garbage traffic affect the performance of Cloudflare's servers? There must be some cost (performance and $$$) to filter this traffic. Was that a consideration when deciding whether to use 1.1.1.1 instead of some other IP address? :)
Cloudflare's new DNS attracting 'gigabits per second' of rubbish
61–70 of 206 posts
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#62Earlier quoted context omitted.
I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…
I think everyone's concern should be that Cloudflare or Google might just replace each IP in their 24h logs with a random UUID and call it anonymized. Both companies can potentially store enough information to correlate DNS requests with regular traffic logs. It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www…
Our business is not about tracking people; it's about selling our service to businesses to make their web sites/APIs/applications faster and more secure.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#63Earlier quoted context omitted.
Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.
It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#64> AT&T Gigapower using 1.1.1.1 on an internal interface on at least one model of router-gateway, the Pace 5268AC Yup. I can't use 1.1.1.1 because my AT&T router is responding to it.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#65Earlier quoted context omitted.
Hello, Are the gigabytes of junk billions of tiny requests or are there large requests as well? Are you finding it more difficult than expected to manage the data? I'm a 1.1.1.1 customer since you launched, thanks a lot for it.
Nope. We have a lot of excess capacity. Doesn’t increase our costs. But, that’s a longer conversation…
Have seen edge traffic charts for major porn hosting companies and the out:in traffic ratio is like 97:3
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#66Awesome, the worlds biggest honeypot? There is literally a finite amount of bandwidth in the existance, let Cloudflare have as much cruft as it wants.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#67Earlier quoted context omitted.
It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.
Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS dir…
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#68I worked with my ISP, htcinc.net to fix routing to 1.1.1.1 this week -- Not sure how they had their core router mis-configured, but it was dropping the traffic.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#69Earlier quoted context omitted.
As an ex-Comcast employee. Seeing stuff like that happen really doesn't surprise me When Comcast first rolled out that data cap nation wide, I started prodding at it one night out of morbid curiosity Turned out that it would silently slurp all HTTP traffic! Once you hit some arbitrary measurement (EG: 50%) it'll immediately start hijacking all HTTP websites you visit and inject a ton of Javascript to put a message ov…
And people wonder why https everywhere is such a necessity now. It should not be necessary to treat your last mile ISP as a hostile entity , but sadly, it often is.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#70Houston has run a study on the traffic being directed towards 1/8 before. http://www.potaroo.net/studies/1slash8/1slash8.html